CVE-2025-14219: Campcodes Retro Basketball Shoes Online Store admin_running.php unrestricted upload
A weakness has been identified in Campcodes Retro Basketball Shoes Online Store 1.0. The impacted element is an unknown function of the file /admin/adminrunning.php. Executing a manipulation of the argument productimage can lead to unrestricted upload. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14219?
CVE-2025-14219 has a high severity due to the potential for unrestricted file uploads.
How do I fix CVE-2025-14219?
To fix CVE-2025-14219, ensure proper validation and sanitization of the product_image argument in the /admin/admin_running.php file.
What impact does CVE-2025-14219 have on my system?
CVE-2025-14219 allows attackers to upload malicious files, which can lead to complete system compromise.
Is CVE-2025-14219 present in all versions of Campcodes Retro Basketball Shoes Online Store?
CVE-2025-14219 specifically affects Campcodes Retro Basketball Shoes Online Store version 1.0.
How can I detect CVE-2025-14219 on my server?
You can detect CVE-2025-14219 by scanning your application for insecure file upload capabilities in the /admin/admin_running.php functionality.